Reading: Ad Fraud on Reddit: HBO Max account used in fake ads, platform says

Ad Fraud on Reddit: HBO Max account used in fake ads, platform says

Published
3 min read
Advertisement

Reddit said an HBO Max account authorized to run advertisements on the platform was compromised and used to push ads containing malicious links, then locked the account and removed the posts. The company said it recently learned about the breach after fake HBO Max ads appeared on Reddit over the past week.

The ads mattered because they did not look like obvious traps. Security researchers Zack Whittaker identified the campaign in which users who clicked through were taken to a page that looked like HBO Max but hid a ClickFix lure. That tactic tries to trick people into copying and pasting a string of text into Windows Command Prompt or Mac Terminal, and when they hit return it can install info-stealing malware that takes passwords, access to logged-in accounts and crypto wallets.

Hudson Rock and ADAMnetworks said the latest ClickFix wave they tracked involved fake ads on Reddit, and the attackers used the compromised HBO Max account to post hundreds of fake but real-looking adverts. The method matters because it uses a trusted advertising account to make the lure look routine, which makes the malicious link harder to spot before the user is pushed toward the terminal command.

- Advertisement -

Reddit said it had contained the account and taken the ads down, but it still has not said how many people were targeted or how many clicked. That leaves the most basic question unanswered: whether this was a narrow run of bad ads or a wider compromise that reached far more users than the company has acknowledged. Warner Brothers Discovery, which owns HBO, did not respond to a request for comment.

The broader backdrop is a rising ClickFix threat that has moved from a rarity to a global campaign aimed at getting people to infect their own machines. Security researchers say some Windows users can reduce exposure by blocking access to Command Prompt or PowerShell, while Mac users have been pointed to BlockBlock as one way to blunt attacks that try to trick them into running commands themselves.

For now, the compromise is over, but the count is not. Reddit has removed the ads and locked the account, yet it has not said how many users clicked them or whether any were ultimately compromised.

Advertisement
Share This Article